Build Security Workflows by Describing What You Need

Blink Copilot turns a written description into a low-code security operations workflow that users can run and edit. Blink says human review and added safeguards are important because a simple interface can make it easy to create actions without understanding their effects.

WTF Index NEUTRAL
◄ Terminator 2 Idiocracy 2 ►

The tool makes security workflow automation easier, while the article notes that users may create actions without understanding their effects and should review them.

Build Security Workflows by Describing What You Need

Blink has introduced Blink Copilot, a tool that creates security operations workflows from written prompts. The company says users can describe a task in ordinary language, inspect the generated workflow, and run it. The launch points to a new approach to automation: users specify the outcome, while the platform builds the steps.

From coding workflows to describing them

Blink CEO Gil Barak describes security operations automation as moving through three periods. In the earliest, specialists wrote code for workflows, a process that could take weeks or months for a single workflow.

Low-code tools made the work faster by letting users assemble components with drag-and-drop interfaces. The platform handled much of the code in the background, reducing how much users had to write themselves.

Blink Copilot represents a further step in that progression. Users enter a description, and the system produces a low-code workflow that can be executed. Barak said the goal of making workflow creation accessible through a simple description had been a long-standing ambition, and that the arrival of ChatGPT at the end of last year made it feel attainable.

Turning a request into security operations

The tool interprets a prompt and uses it to assemble a workflow. As an example, Blink gave a request to create a ServiceNow ticket for the relevant event engineer for each issue in Wiz, with a 48-hour deadline to fix it. Copilot would translate that request into a workflow.

That example illustrates the intended role of the tool: translate a stated operational task into linked actions across services. Blink is focused on security operations, distinguishing its purpose from Ansible Lightspeed, which had been announced the previous week at the Red Hat Summit for automating IT operations.

Users can work with the generated result after it is created. They can change workflow elements, add components, inspect how an individual step works, and review or edit the underlying code. That makes the prompt a starting point for building a workflow, rather than the only way to control it.

A broad component library and multiple models

Blink says Copilot draws on a library of more than 7,000 workflow components. The components cover areas such as email security, cloud security, and network security, giving the system building blocks for different operational tasks.

The company is also working with several large language model providers, including Microsoft, Google, and OpenAI. Barak said Blink designed the product so it can connect to multiple models and try them out. He also said the company trains the system using what it builds, including customer data and its actions and integrations.

This design gives Blink flexibility in how it develops the tool. The available components and integrations help define the actions Copilot can assemble, while the ability to inspect and edit the result gives users a way to see how a generated workflow is structured.

Ease of use raises a need for safeguards

Making workflow creation easier also creates a risk: a person could build a workflow without the technical knowledge needed to understand the consequences of its actions. Barak acknowledged that concern and said people should remain involved, with someone responsible for checking a workflow before it is published.

Barak described a shift in what customers worry about. Previously, companies discussed the difficulty of hiring and retaining security engineers. With a tool that makes workflows easier to create, customers are asking how to add guardrails and protect themselves from mistakes.

Blink says it is adding guardrails. Human review is also part of the approach Barak described: a workflow can be generated quickly, but a person should still be accountable for assessing it before it goes live. That distinction matters because a workflow that is easy to assemble can still trigger consequential actions.

Blink, which has raised $26 million, is making Blink Copilot generally available today, according to the article. The product's promise is to shorten the path from an operational request to an executable workflow; its adoption will also depend on how effectively users can review and control the actions the system proposes.